← Back

CVE-2021-1470

nvd nist
Published: Nov 15, 2024Modified: Jun 24, 2025

JSON object

Loading...
4.9
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Exploitability: 1.2 / Impact: 3.6
Source: psirt@cisco.com (Secondary)

Description

A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability is due to improper input validation of SQL queries to an affected system. An attacker could exploit this vulnerability by authenticating to the application and sending malicious SQL queries to an affected system. A successful exploit could allow the attacker to modify values on or return values from the vManage database or the underlying operating system.Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.

Affected (49)

1 product
Catalyst Sd Wan Manager
Configuration A
49 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 17.2.10
Version 17.2.4
Version 17.2.5
Version 17.2.6
Version 17.2.7
Version 17.2.8
Version 17.2.9
Version 18.2.0
Version 18.3.0
Version 18.3.1.1
Version 18.3.1
Version 18.3.3.1
Version 18.3.3
Version 18.3.4
Version 18.3.5
Version 18.3.6.1
Version 18.3.6
Version 18.3.7
Version 18.3.8
Version 18.4.0.1
Version 18.4.0
Version 18.4.1
Version 18.4.302
Version 18.4.303
Version 18.4.3
Version 18.4.4
Version 18.4.501_es
Version 18.4.5
Version 18.4.6
Version 19.0.0
Version 19.0.1a
Version 19.1.0
Version 19.2.097
Version 19.2.098
Version 19.2.099
Version 19.2.0
Version 19.2.1
Version 19.2.2
Version 19.2.31
Version 19.2.32
Version 19.2.3
Version 19.2.929
Version 19.3.0
Version 20.1.1.1
Version 20.1.12
Version 20.1.1
Version 20.1.2
Version 20.1.2_937
Version 20.3.1

Timeline

No history available yet.